Skip to content

DNS Lookup guide

Tool guide. Updated .

How DNS resolution works, what each record type in the XGM DNS Lookup means, how to read the findings and how to troubleshoot common DNS problems.

How a DNS lookup works

When a browser or mail server needs www.example.com, it asks a recursive resolver, usually run by an internet provider, a company or a public DNS service. The resolver finds the answer by following delegations from the root servers to the servers for com and then to the authoritative name servers for example.com. It caches the answer for the time-to-live (TTL) set in the record.

The XGM DNS Lookup asks its own resolver from the XGM server, so you see what a typical resolver on the internet sees, not what your office network or laptop cache says. That makes it useful for checking a change from outside, or for comparing with what a colleague sees. Below the records, a propagation table asks the same question to Cloudflare, Google, Quad9, OpenDNS, AdGuard, Level3 and Yandex and to one authoritative name server of the zone, with the TTL, the response time and the DNSSEC AD flag of each. Copy as dig copies the equivalent dig command.

Resolving www.example.comA resolver asks the root servers, then the com servers, then the example.com name servers, and caches the final answer for its TTL.Client asks a recursive resolverWhat is the A record of www.example.com?Root serversRefer the resolver to the name servers for comcom serversRefer the resolver to the name servers ofexample.com (NS records)example.com name serversAnswer: www.example.com A 192.0.2.80, TTL 3600Resolver caches and answersLater clients get the cached answer until theTTL runs out
A resolver asks the root servers, then the com servers, then the example.com name servers, and caches the final answer for its TTL.

How to use the DNS Lookup

  1. Open the DNS Lookup and enter a domain or host name, such as example.com or www.example.com, or an IP address for a reverse lookup. Pasted URLs are reduced to the host name.
  2. Keep Common types to query A, AAAA, MX, NS, TXT and CNAME records in one run, or pick one type (A, AAAA, CNAME, MX, NS, TXT, SOA, CAA or SRV) to see that type with its TTL.
  3. Read the table of records, then the findings below it. A dig-style raw output is available for copying into tickets.
  4. Use Run next to continue with SPF, DMARC, SSL or other checks for the same name, or Compare to put two domains side by side.

An IP address always runs a reverse (PTR) lookup, for example 8.8.8.8 returns dns.google. The tool then checks whether that name resolves back to the same address, which is what mail receivers call forward-confirmed reverse DNS. The record type is part of the permalink (/tools/dns?d=example.com&type=CAA), and the old nslookup and Reverse DNS tools now open this page.

Record types in the result

Records shown by the DNS Lookup
TypeContainsUsed for
AAn IPv4 addressWebsites and services over IPv4
AAAAAn IPv6 addressWebsites and services over IPv6
CNAMEAn alias pointing to another namePointing subdomains at hosted services
MXMail server host name with a preference numberDelivering email to the domain
NSAuthoritative name server host namesDelegating the zone
TXTFree text stringsSPF, domain verification, policies such as DMARC at _dmarc
Typical records for example.com
example.com.      3600 IN A     192.0.2.80
example.com.      3600 IN AAAA  2001:db8::80
www.example.com.  3600 IN CNAME example.com.
example.com.      3600 IN MX    10 mail.example.com.
example.com.     86400 IN NS    ns1.example.net.
example.com.      3600 IN TXT   "v=spf1 include:_spf.mail.example.net -all"

TXT records often contain several strings. Long values such as SPF records or DKIM keys are split into quoted chunks of up to 255 characters, which receivers join. The result table shows them as the resolver returns them.

What the findings mean

DNS Lookup findings
FindingSeverityMeaning and action
No records foundCriticalThe name does not exist (NXDOMAIN) or has none of the queried types. Check spelling and whether the zone is delegated.
Lookup failed for …WarningThe resolver timed out or no name server answered for those types. The records are unknown, not necessarily empty; try again.
CNAME next to other recordsWarningA name with a CNAME must not have other records (RFC 1034). Remove the conflicting records or the alias.
No A, AAAA or CNAME recordInfoBrowsers cannot open the name as a website. Normal for mail-only domains.
No IPv6 (AAAA) recordInfoIPv6-only clients reach the site only through translation. Add AAAA when your host supports IPv6.
n records foundPassedAnswers came back; they may be cached for up to the TTL.

Apex CNAMEs

The bare domain (example.com) cannot be a CNAME, because it must also hold NS and SOA records. DNS providers offer ALIAS, ANAME or CNAME-flattening features that answer with A and AAAA records instead.

Why a change is not visible yet

"DNS propagation" is really caching. When you change a record, resolvers that cached the old answer keep serving it until its TTL expires; there is no push to the internet. A record with a TTL of 86400 seconds can take up to a day to change everywhere, while one with 300 seconds changes within five minutes.

  • Before planned changes, lower the TTL of the records you will change and wait at least the old TTL.
  • Check the authoritative name servers directly with dig @ns1.example.net example.com A to confirm the new value is published; the propagation table does this for one of them.
  • If the propagation table shows different answers while the authoritative server already has the new value, the others are serving a cached answer; a CDN that answers by location can also return different addresses on purpose.
  • Negative answers are cached too: a name that did not exist when a resolver asked may keep returning NXDOMAIN for the zone's negative-caching time.
  • Name server changes at the registrar depend on the TTL of NS records in the parent zone, which you cannot lower.

The domain migration checklist puts these steps in order for larger changes such as moving DNS providers.

Troubleshooting common problems

Symptoms and likely causes
SymptomLikely causeCheck
Website works for some people, not othersOld cached record, or different AAAA and A resultsCompare A and AAAA values; wait for the TTL
New subdomain does not resolveRecord added at a DNS provider that is not authoritativeCompare NS records with where you edited the zone
Email verification TXT not foundRecord added under the wrong name, for example with the zone name doubledLook for example.com.example.com style names
Intermittent lookup failuresOne of the name servers is down or out of syncQuery each NS directly
Validating resolvers fail, others workDNSSEC chain brokenSee the DNSSEC guide

Many DNS panels append the zone name automatically. Entering _dmarc.example.com as the host name in such a panel creates _dmarc.example.com.example.com, which nobody queries. Enter only the part before the zone, such as _dmarc.

FAQ

Which resolver does the DNS Lookup use?

The resolver configured on the XGM server. Answers reflect a normal recursive resolver on the internet, including its cache, not your local network.

Why do I see different results than on my computer?

Your computer, router or company resolver may have a cached answer, a split-horizon internal zone, or a different view. Compare with the authoritative servers using dig @<name server>.

Can I query SOA, CAA or SRV records?

Yes. Pick the type in the Record type selector; single-type lookups also show the TTL. Common types query the six most used types in one run.

What does a trailing dot in a host name mean?

It marks a fully qualified name, such as mail.example.com.. In zone files, names without the dot are relative to the zone, which is a common source of doubled names.

How long does DNS propagation take?

As long as the TTL of the old record in resolvers' caches. Lower TTLs before planned changes to make them take effect quickly.

Why does a lookup say failed instead of empty?

A timeout or unreachable name server means the resolver does not know the answer. XGM reports that separately so a temporary problem is not mistaken for a missing record.

Does XGM store the domains I look up?

The lookup is not stored with a result. Recent checks are kept only in your browser, and you can clear them on the tool page.

Sources